1 Commits
Author SHA1 Message Date
sneak 0d5b3b23ea Rewrite the -count=1 note to match the current files (closes #77)
check / check (push) Successful in 50s
The note under the canonical Go `make test` example in `prompts/REPO_POLICIES.md` still named the cache-busting build argument that `--no-cache` replaced, and said Go's cache was baked into earlier image layers.

It now says where Go's test result cache can replay a pass: on a developer's machine, where the Makefile target runs, so `-count=1` stays on both invocations. The `test` phase of the `Dockerfile` has nothing to replay: its base image holds no result for the repo's tests and no earlier step runs one.

The first paragraph no longer says the rerun would replay a failure: Go stores only passes.

Model: opus-5-5
2026-10-04 03:20:01 +00:00
5 changed files with 53 additions and 66 deletions
-3
View File
@@ -17,10 +17,7 @@
# stage that compiles runs `git describe --tags --always` on .git, which # stage that compiles runs `git describe --tags --always` on .git, which
# does not need .git/config; that file can hold a credential, such as a # does not need .git/config; that file can hold a credential, such as a
# password in a remote URL or the token the CI checkout step stores there. # password in a remote URL or the token the CI checkout step stores there.
# Each submodule keeps a config with the same exposure in its git directory
# under .git/modules/, nested again for a submodule's own submodules.
.git/config .git/config
.git/modules/**/config
# Agent scratch: one full checkout of the repo per in-flight agent. # Agent scratch: one full checkout of the repo per in-flight agent.
# Anchored because it occurs once where agents run at the repo root. # Anchored because it occurs once where agents run at the repo root.
-6
View File
@@ -27,12 +27,6 @@ fmt-check, and commit.
can replay a pass: on a developer's machine, where the Makefile target runs, can replay a pass: on a developer's machine, where the Makefile target runs,
and not in the `test` phase of the `Dockerfile`, whose base image and earlier and not in the `test` phase of the `Dockerfile`, whose base image and earlier
steps hold no result for the repo's tests. steps hold no result for the repo's tests.
- 2026-10-04: The canonical `.dockerignore` now also keeps out each submodule's
`config` (issue 75). A submodule's git directory lives under `.git/modules/`,
nested again for its own submodules, and its `config` can hold a credential
just like `.git/config`. The pattern `.git/modules/**/config` covers every
depth and leaves the top-level `.git` that `git describe` reads untouched.
`REPO_POLICIES.md` and both checklists say so in the same words.
- 2026-10-03: Fixed two defects in the canonical Go `Dockerfile` example (issue - 2026-10-03: Fixed two defects in the canonical Go `Dockerfile` example (issue
73). The test phase now uses the Debian Go image, since `-race` needs cgo and 73). The test phase now uses the Debian Go image, since `-race` needs cgo and
the alpine image has no C compiler, so the phase failed before running a test. the alpine image has no C compiler, so the phase failed before running a test.
+21 -23
View File
@@ -1,6 +1,6 @@
--- ---
title: Existing Repo Checklist title: Existing Repo Checklist
last_modified: 2026-10-04 last_modified: 2026-10-03
--- ---
Use this checklist when beginning work in a repo that may not yet conform to our Use this checklist when beginning work in a repo that may not yet conform to our
@@ -59,28 +59,26 @@ with your task.
here run anywhere other than the repo root, the anchored entry misses here run anywhere other than the repo root, the anchored entry misses
`services/api/.claude/`: add anchored entries for those directories. `services/api/.claude/`: add anchored entries for those directories.
- [ ] If the repo embeds a version in a binary: `.dockerignore` lets `.git` into - [ ] If the repo embeds a version in a binary: `.dockerignore` lets `.git` into
the build context. It keeps out `.git/config` and each submodule's the build context. It keeps out `.git/config`, which `git describe` does
`config` under `.git/modules/` at any depth (`.git/modules/**/config`), not need and which can hold a credential: a password in a remote URL, or
which `git describe` does not need and which can hold a credential: a the token the CI checkout step stores there. The stage that compiles has
password in a remote URL, or the token the CI checkout step stores there. `git` (the Debian Go image has it; an alpine one needs
The stage that compiles has `git` (the Debian Go image has it; an alpine `apk add --no-cache git`) and takes the version from the `VERSION` build
one needs `apk add --no-cache git`) and takes the version from the argument when one is given, otherwise from `git describe --tags --always`.
`VERSION` build argument when one is given, otherwise from That gives the tag on a tagged commit; on a later commit, the tag, the
`git describe --tags --always`. That gives the tag on a tagged commit; on number of commits since it and the short commit (`v1.2.3-4-gabc1234`); and
a later commit, the tag, the number of commits since it and the short the short commit when no tag is reachable. The stage that compiles also
commit (`v1.2.3-4-gabc1234`); and the short commit when no tag is marks its working directory safe for git
reachable. The stage that compiles also marks its working directory safe (`git config --system --add safe.directory /src`): a context sent as a tar
for git (`git config --system --add safe.directory /src`): a context sent stream keeps the sender's file owners, and git refuses a checkout owned by
as a tar stream keeps the sender's file owners, and git refuses a checkout another user, so the version would come out empty. `ARG VERSION` has no
owned by another user, so the version would come out empty. `ARG VERSION` default, and the build fails if the context carries `.git` and the version
has no default, and the build fails if the context carries `.git` and the still comes out empty, `dev` or `unknown`. A plain `docker build .` with
version still comes out empty, `dev` or `unknown`. A plain no build arguments must succeed; a Dockerfile that refuses an empty build
`docker build .` with no build arguments must succeed; a Dockerfile that argument drops that refusal and keeps the argument. `script/docker` and
refuses an empty build argument drops that refusal and keeps the argument. `script/cibuild` pass the version they compute on the host; it takes
`script/docker` and `script/cibuild` pass the version they compute on the precedence. A tag-derived version additionally needs `fetch-depth: 0` on
host; it takes precedence. A tag-derived version additionally needs the CI checkout step, which clones shallow and fetches no tags by default.
`fetch-depth: 0` on the CI checkout step, which clones shallow and fetches
no tags by default.
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on - [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on
push — reference push — reference
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml` `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
+18 -19
View File
@@ -1,6 +1,6 @@
--- ---
title: New Repo Checklist title: New Repo Checklist
last_modified: 2026-10-04 last_modified: 2026-10-03
--- ---
Use this checklist when creating a new repository from scratch. Follow the steps Use this checklist when creating a new repository from scratch. Follow the steps
@@ -68,24 +68,23 @@ Template files can be fetched from:
will run them in subdirectories, `services/api/.claude/` needs its own will run them in subdirectories, `services/api/.claude/` needs its own
anchored entry. anchored entry.
- If the image embeds a version in a binary: `.dockerignore` lets `.git` - If the image embeds a version in a binary: `.dockerignore` lets `.git`
into the build context. It keeps out `.git/config` and each submodule's into the build context. It keeps out `.git/config`, which `git describe`
`config` under `.git/modules/` at any depth (`.git/modules/**/config`), does not need and which can hold a credential: a password in a remote URL,
which `git describe` does not need and which can hold a credential: a or the token the CI checkout step stores there. The stage that compiles
password in a remote URL, or the token the CI checkout step stores there. has `git` (the Debian Go image has it; an alpine one needs
The stage that compiles has `git` (the Debian Go image has it; an alpine `apk add --no-cache git`) and takes the version from the `VERSION` build
one needs `apk add --no-cache git`) and takes the version from the argument when one is given, otherwise from `git describe --tags --always`.
`VERSION` build argument when one is given, otherwise from That gives the tag on a tagged commit; on a later commit, the tag, the
`git describe --tags --always`. That gives the tag on a tagged commit; on number of commits since it and the short commit (`v1.2.3-4-gabc1234`); and
a later commit, the tag, the number of commits since it and the short the short commit when no tag is reachable. The stage that compiles also
commit (`v1.2.3-4-gabc1234`); and the short commit when no tag is marks its working directory safe for git
reachable. The stage that compiles also marks its working directory safe (`git config --system --add safe.directory /src`): a context sent as a tar
for git (`git config --system --add safe.directory /src`): a context sent stream keeps the sender's file owners, and git refuses a checkout owned by
as a tar stream keeps the sender's file owners, and git refuses a checkout another user, so the version would come out empty. `ARG VERSION` has no
owned by another user, so the version would come out empty. `ARG VERSION` default, and the build fails if the context carries `.git` and the version
has no default, and the build fails if the context carries `.git` and the still comes out empty, `dev` or `unknown`. A plain `docker build .` with
version still comes out empty, `dev` or `unknown`. A plain no build arguments must succeed; a Dockerfile that refuses an empty build
`docker build .` with no build arguments must succeed; a Dockerfile that argument drops that refusal and keeps the argument.
refuses an empty build argument drops that refusal and keeps the argument.
- The Dockerfile carries a `lint` phase and a `test` phase, each invoking - The Dockerfile carries a `lint` phase and a `test` phase, each invoking
its tool directly rather than through `make` or `script/`, and the final its tool directly rather than through `make` or `script/`, and the final
stage carries a `COPY --from=` of a harmless file from each so the image stage carries a `COPY --from=` of a harmless file from each so the image
+14 -15
View File
@@ -239,21 +239,20 @@ style conventions are in separate documents:
- If the project requires CGO or system libraries for linting (e.g. - If the project requires CGO or system libraries for linting (e.g.
`vips-dev`), install them in the lint phase with `apk add`. `vips-dev`), install them in the lint phase with `apk add`.
- `.dockerignore` lets `.git` into the build context. It keeps out - `.dockerignore` lets `.git` into the build context. It keeps out
`.git/config` and each submodule's `config` under `.git/modules/` at any `.git/config`, which `git describe` does not need and which can hold a
depth (`.git/modules/**/config`), which `git describe` does not need and credential: a password in a remote URL, or the token the CI checkout step
which can hold a credential: a password in a remote URL, or the token the stores there. The stage that compiles has `git` (the Debian Go image has
CI checkout step stores there. The stage that compiles has `git` (the it; an alpine one needs `apk add --no-cache git`) and takes the version
Debian Go image has it; an alpine one needs `apk add --no-cache git`) and from the `VERSION` build argument when one is given, otherwise from
takes the version from the `VERSION` build argument when one is given, `git describe --tags --always`. That gives the tag on a tagged commit; on
otherwise from `git describe --tags --always`. That gives the tag on a a later commit, the tag, the number of commits since it and the short
tagged commit; on a later commit, the tag, the number of commits since it commit (`v1.2.3-4-gabc1234`); and the short commit when no tag is
and the short commit (`v1.2.3-4-gabc1234`); and the short commit when no reachable. The stage that compiles also marks its working directory safe
tag is reachable. The stage that compiles also marks its working directory for git (`git config --system --add safe.directory /src`): a context sent
safe for git (`git config --system --add safe.directory /src`): a context as a tar stream keeps the sender's file owners, and git refuses a checkout
sent as a tar stream keeps the sender's file owners, and git refuses a owned by another user, so the version would come out empty. `ARG VERSION`
checkout owned by another user, so the version would come out empty. has no default, and the build fails if the context carries `.git` and the
`ARG VERSION` has no default, and the build fails if the context carries version still comes out empty, `dev` or `unknown`. A plain
`.git` and the version still comes out empty, `dev` or `unknown`. A plain
`docker build .` with no build arguments must succeed; a Dockerfile that `docker build .` with no build arguments must succeed; a Dockerfile that
refuses an empty build argument drops that refusal and keeps the argument. refuses an empty build argument drops that refusal and keeps the argument.